CVE-2021-34249

HIGH

Online Book Store 1.0 - SQL Injection via ID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-34249. PoCs published by Moaaz Taha.

AI-analyzed exploit summary This exploit demonstrates a Union-Based blind SQL injection vulnerability in Online Book Store 1.0 via the 'id' parameter. It uses sqlmap to automate the exploitation process to retrieve database information.

Description

SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.

Exploits (1)

exploitdb SCANNER
by Moaaz Taha · textwebappsphp
https://www.exploit-db.com/exploits/48775

This exploit demonstrates a Union-Based blind SQL injection vulnerability in Online Book Store 1.0 via the 'id' parameter. It uses sqlmap to automate the exploitation process to retrieve database information.

Classification
Scanner 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Online Book Store 1.0
No auth needed
Prerequisites: Access to the target URL · sqlmap installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry
https://www.exploit-db.com/exploits/48775

Scores

CVSS v3 7.5
EPSS 0.0123
EPSS Percentile 65.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
online_book_store_project/online_book_store 1.0
Published Feb 24, 2023
Tracked Since Feb 18, 2026